Malware

Win32/Kryptik.HMCT removal instruction

Malware Removal

The Win32/Kryptik.HMCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMCT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
securebiz.org
astdg.top

How to determine Win32/Kryptik.HMCT?


File Info:

crc32: 5723C962
md5: 4382c1cea8c5f3abab3c4253e48256e8
name: 4382C1CEA8C5F3ABAB3C4253E48256E8.mlw
sha1: 22bb66dd66a57bca01f3090200130e7564062b5e
sha256: 28057057264aaac51bd431a2f10e13be59c005c33cb872aecc180219d1da5525
sha512: f26840631bad9a3a4f5794fa7385bfa973f1b2bc5f3f9bbcb4d0410c4ebfe1304bdc7cda3879b3adac8a838c2a5663c2fe2ba100101a9c4a8bd8d5edb41ccc4c
ssdeep: 24576:LDthNE1sosbICvKpm63Jg3vNacFkys+Y3J:9EKotpNZglao0+C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020b 0x0085

Win32/Kryptik.HMCT also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00581a2e1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.14558
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.Z5
ALYacTrojan.GenericKDZ.77150
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00581a2e1 )
Cybereasonmalicious.d66a57
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HMCT
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-9886641-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKDZ.77150
MicroWorld-eScanTrojan.GenericKDZ.77150
Ad-AwareTrojan.GenericKDZ.77150
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34170.XqW@ausOMjnH
TrendMicroRansom_StopCrypt.R06CC0DIG21
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.4382c1cea8c5f3ab
EmsisoftTrojan.GenericKDZ.77150 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.nkp
AviraTR/AD.InstaBot.nutat
MicrosoftRansom:Win32/StopCrypt.MGK!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Injuke
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataTrojan.GenericKDZ.77150
AhnLab-V3Trojan/Win.Raccrypt.R437574
Acronissuspicious
McAfeePacked-GDT!4382C1CEA8C5
MAXmalware (ai score=84)
VBA32Trojan.Azorult.a
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_StopCrypt.R06CC0DIG21
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
IkarusTrojan.Win32.Glupteba
FortinetW32/Kryptik.HMEJ!tr
AVGWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.HMCT?

Win32/Kryptik.HMCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment